# The Grant Is User Shaped And Not Data Shaped: Start With The Connectors, And The Template Vault Is The Product

**version** v0.33.70
**date** 12 September 2026
**from** Human (project lead)
**to** Whoever builds the first vault, whoever writes the first five policies, and whoever decides what the risk product's front page says

**type** Dev brief (the end to end flow for shipping one policy, from the first page a visitor sees to the delivered vault)

*Sixth of the eleventh and written on the twelfth, and the first document since the ABP acquired a name to specify how one gets sold, made and delivered. Both the corpus and the outside were searched. The outside search was aimed at one thing, which is what a connector actually grants when somebody plugs an assistant into their mail or their files, and it came back with the strongest material in this corpus to date: there is no narrower scope than the whole mailbox, the default file search corpus already includes everything other people shared with you, the enterprise controls narrow by application and never by data, and in at least four places the advertised capability and the granted scope contradict each other on products people use daily. Limitations: four of those contradictions could not be resolved without testing, and testing somebody else's system is forbidden here; no pricing is proposed; and the state of the refactored risk product was described in the memo and not inspected.*

---

## What This Is

The specification for shipping one behaviour policy end to end, and the choice of which five to make first: **the memo states that the risk product has been refactored to work directly from an agent and the behaviour policy has a first pass, so the next thing needed is an end to end policy that can actually be shipped, meaning the whole flow through execution, delivery and eventually purchase, and what the customer experiences and what we hand over; it says the long term vision of the risk product, which is mapping the risk of the organisation, should stay visible on the website but move into a section, because the short term is selling customised policies and the first thing a visitor should meet is an invitation to buy one, prefaced by the question of whether they know what their agents are doing and what the grant and the mandate actually are, with examples to look at; it says what is being sold is the graph capability, the ability to produce via a vault a policy describing what the agent does, and that the first policies should be for things we can touch, naming a coding agent and a build platform, and then, better, the common pattern being promoted everywhere, which is giving an assistant access to an inbox, a shared folder or a drive; it says to start from the vanilla deployments already in the capability game and transform them into policies, connect them to the standards and the regulations, and build the first version of the vault, because the vault becomes the product and the delivery mechanism, with public and private versions since a read key can be shared; the first finding is that the connector examples are the right place to start and are stronger than the memo suggests, because the grant they create is user shaped rather than data shaped, meaning the only mail scope in existence that reads a message reads every message, the default file search corpus is defined by its owner as files owned by or shared to the user, the tenant wide search in one vendor's own words makes site specific narrowing unsupported, and no mechanism exists anywhere to say this assistant may read my files except the folder the legal team shared with me; the second is that in at least four places the published capability and the granted scope contradict each other on these products, which is exactly what a behaviour policy surfaces and is therefore the demonstration rather than an inconvenience; the third is that these policies map to data protection law before they map to the artificial intelligence regulation, because an inbox is other people's correspondence and the sub delegation provision is one sentence, which makes the first standards mapping the one every buyer already has somebody accountable for; the fourth is that the memo's instruction about the front page belongs to the risk product's site and not to the ABP site, because the free library and the paid instance were separated on 26 August and a checkout on the library prices the free side; and the fifth is that the thing being sold is not the document and not even the vault but the template and the shape library, because the first policy will be made by hand and the business only exists if the second costs less than the first.** New contributions: **the twelve stage flow with what can ship this week; the five first policies with the scopes behind them; the user shaped finding and the property the capability grammar is missing; the advertised against granted contradiction as the demonstration; the read key as shareable proof and what that is worth; and the rule that the template is the product.**

## Where The Buy Button Goes

**The memo says the first thing a visitor sees should be an invitation to buy a policy. That is right, and it belongs on the risk product's site.** Three sites now have three jobs and keeping them separate is the 26 August ruling rather than tidiness.

| Site | Job | Carries a price |
|---|---|---|
| **The policy site** | The argument, the model, the examples, the data, the docs. **The free public library** | **No** |
| **The risk product's site** | The offer. Do you know what your agents can do, here is what one looks like, buy one | **Yes, by linking** |
| **The store** | The checkout and the payment rail | **Yes** |

**A checkout on the library prices the free side of the line**, which is the error corrected in writing on 10 September. The library's job is to make the argument so well that somebody wants the instance.

**On the memo's proposed opening**, which is close to right and needs one change. The sequence *do you know what your agents can do, here is an example, buy one* is correct. **But the question and the example are the library's content**, so the risk product's front page carries the question, one worked example, and the link. The library carries all five examples, the model and the data.

**And the long term vision moves to a section rather than off the site.** The memo is right that mapping the risk of the organisation is the destination and should stay visible. It is also right that it cannot be the front page while the thing being sold is one document. **The front page sells the label. The section describes the estate the label is the first step into.**

## Start With The Connectors, Because The Grant Is User Shaped

**The memo's second thought is better than its first.** Policies for a coding agent and a build platform are useful and they are about where an agent runs. **Policies for an assistant connected to an inbox, a shared folder or a drive are about whose material it reaches, and that is the argument.**

**Here is what those grants actually are, from the vendors' own documentation.**

**Mail.** The narrowest scope that lets anything read a message reads the whole mailbox. The publisher's own description is *view your email messages and settings*. There is no scope that filters by sender, by label or by date. **The only scope that excludes message bodies is not used by any of these integrations.** So the grant is: every message in the mailbox, including every message anybody ever sent you in confidence.

**Files.** The scope in use is described by its publisher as *view and download all your Drive files*. And the default search corpus for that grant is defined by the same publisher as **files owned by or shared to the user**. **So everything any colleague, client or counterparty has ever shared with that person is inside the default search on day one**, without anybody choosing it.

**The enterprise file estate.** One vendor's own connector documentation states that site specific permissioning **is not supported because the underlying search is tenant wide**. That is a published admission that the intended narrowing mechanism is unavailable, and the only remaining lever is revoking the permission wholesale.

**Shared mail and shared files in the corporate suite.** The delegated permissions in use include one described as *read mail a user can access, including their own and shared mail*, one as *read all files the signed in user can access*, and one covering documents across all site collections. **None of those three individually requires an administrator's consent.**

**The storage service.** The official remote server for one widely used file service requests eight scopes including write and sharing, and there is no folder scoped variant of it.

**And the default posture is permissive.** On a default configured business domain at the largest provider, third party application access is allowed unless an administrator changes it. **A person can connect an assistant to their work mailbox with no administrator involved.**

**The finding, in one sentence: the grant is user shaped and not data shaped.** The unit of restriction is the application and the tool. There is no supported way to say *this assistant may read my files except the folder the legal team shared with me*, or *my inbox except messages from outside the company*. **That is the sentence the first five policies exist to make visible.**

## Which Makes These The Sub Delegation Argument, Made Concrete

**A mailbox is mostly other people's writing. A shared folder is mostly other people's files.** So a connector grant is, by construction, a grant over material that was entrusted rather than owned.

**And that is a provision rather than an analogy.** The data protection regulation says in one sentence that a processor shall not engage another processor without prior written authorisation of the controller, and that the first stays liable for the second. A professional regulator wrote on 17 August 2026 that putting client documents into a public model tool is to place them in the public domain. Every ordinary confidentiality agreement lists permitted recipients and none of them lists a model provider.

**So the first standards mapping is the data protection regulation, not the artificial intelligence regulation.** That is a reordering with a real consequence: **every organisation already has somebody accountable for data protection**, and almost none has anybody accountable for the newer instrument, whose deployer obligations were in any case deferred to December 2027 and reach only high risk systems.

**The honest gap, and it should be stated on the page.** No regulator has yet addressed head on the question of third party personal data sitting in somebody's mailbox being disclosed to an assistant by that person's own consent. The nearest published hook is a national regulator's assessment of 8 January 2026, which warns about systems connected to databases not needed for their tasks and flags the difficulty of determining controller and processor responsibilities through the supply chain. **That is a hook and not a ruling, and the example policies should cite it as what it is.**

## The Contradiction Is The Demonstration

**Here is the thing that makes these examples land, and it was not in the memo.**

**In at least four places, the advertised capability and the granted scope disagree**, on products in daily use:

| What is advertised | What the published scopes permit |
|---|---|
| Share, move and trash files | The two scopes in the grant are a read only scope and a per file scope. Neither authorises acting on a pre existing file |
| Create, update and delete calendar events | The publisher's own list of scopes for that service is read only |
| Label and unlabel mail threads | Neither scope in the published grant authorises label mutation |
| Search files | Whether the shared drive flags are set is undocumented, so whether team drives are in the corpus in practice is unknown |

**Four contradictions, on four features, between two vendors' own pages.** Nobody is being dishonest. **The marketing copy and the scope list are maintained by different people and nothing reconciles them**, which is precisely the condition a behaviour policy exists to expose.

**So the first published policy carries a section that no competitor's template can have: where the published description and the granted permission disagree.** It is checkable, it uses only the vendors' own documents, it attaches no adjective to anybody, and it demonstrates the product's whole value in one table.

**One rule around it, and it is not negotiable.** These contradictions **cannot be resolved by testing**, because testing somebody else's system to find out what it does is the thing forbidden by the first hard rule. **They are published as unresolved, sourced to both pages, with the date.** An unresolved contradiction honestly stated is worth more than a resolved one obtained by probing.

## What The Capability Grammar Is Missing

**The twenty three primitives carry a reach: project, host, tenant, world, self. They do not carry whose.**

`read.record.mailbox` would say the agent can read a mailbox. It would not say that the mailbox contains correspondence from clients who never agreed to this. **Reach answers how far. It does not answer whose.**

**The minimum fix is a property rather than a new dimension**, because a fourth element multiplies the grammar and the memo is right that this should stay simple:

| Property | Values | Meaning |
|---|---|---|
| `material` | `own`, `organisation`, `third_party`, `mixed` | Whose material the capability reaches |

**Almost every connector capability is `mixed`, and that is the finding.** A mailbox is mixed. A shared drive is mixed. A personal notes folder is `own`. **The value of the property is that `mixed` cannot be made `own` by any setting the vendor offers**, which is the user shaped finding expressed as data rather than as a paragraph.

**This is a proposal to the shared capability data and it belongs in the open repository as a proposal**, with its evidence, through the same mechanism as any other change to those files.

## The Five First Policies

| # | Shape | Why it is on the list | What it demonstrates |
|---|---|---|---|
| **1** | Assistant connected to a personal mailbox | The most promoted pattern of the year | The narrowest read scope is the whole mailbox |
| **2** | Assistant connected to a work mailbox | The same grant, a different consequence | **Shared mail is in scope and no administrator was asked** |
| **3** | Assistant connected to a personal cloud drive | Familiar, low stakes, easy to read | The default corpus is owned **or shared to** the user |
| **4** | Assistant connected to a corporate file estate | The enterprise case | **Site specific narrowing is unsupported, per the vendor** |
| **5** | Coding agent on a developer machine, confirmations on and off | Already profiled in the capability game | **One setting, two documents, the same grant and a different barrier** |

**Build five first, because it is already in the data and it proves the method with no new research.** Then one and three, which are the ones a stranger recognises. Then two and four, which are the ones somebody buys.

**And every one of them is a derived document, not a measured one.** The rows come from vendor documentation read on a date, not from observation. **The provenance line says so, in the same place the capability map says twenty one of ninety nine rows were measured.**

## The Twelve Stages, And What Can Ship This Week

| # | Stage | What happens | State |
|---|---|---|---|
| 1 | **Encounter** | The question on the risk product's front page | **Content, ship this week** |
| 2 | **Self select** | Which of these shapes is yours | **A page of five, ship this week** |
| 3 | **Draft** | The pre computed policy for that shape, free, instant, no account | **Ship this week if the five exist** |
| 4 | **Correct** | They tell us where it is wrong. **This is the conversion moment and the elicitation at the same time** | **A conversation, ship this week** |
| 5 | **Purchase** | On the store, against the existing tiers | The rail exists, the offer page does not |
| 6 | **Provision** | Clone the template vault, seed it with the corrected draft | **Needs the template vault** |
| 7 | **Elicit the mandate** | The part that needs a person or a structured set of questions | Needs the question set |
| 8 | **Measure the grant** | From the shape, the credentials and the connectors actually enabled | Needs the shape library |
| 9 | **Compute** | Delta, label, leaflet, all derived and none authored | Needs the computation |
| 10 | **Deliver** | The vault, and a read key they can share | **Needs the template vault** |
| 11 | **Live** | Recompute when an input changes; the history accumulates | Needs the receiver |
| 12 | **Uplift** | The twin, the risk score, the standards mapping | Later, and signed by somebody who did not sell stages one to ten |

**Stages one to four can ship this week and they are the whole sales motion.** They need five documents and a page. **They need no vault, no account, no integration and no access to anybody's environment.**

**Stages six to ten are one build: the template vault.** That is the next engineering task and it is the product.

## The Vault Is The Delivery, And The Read Key Is The Feature

**The memo is right that the vault becomes the product, and one precision matters.** What is sold is a **clone of a template vault**, seeded with the customer's own corrected draft, containing:

- the mandate as elicited,
- the grant as measured, with every row's provenance,
- the delta as derived, with the versions of both inputs pinned,
- the label and the leaflet, computed,
- the history, as it accumulates,
- and the validity statement.

**Nothing in it is authored except the mandate**, which is the only thing the customer knows and we do not.

**The read key is the part the memo mentions in passing and it is worth more than it sounds.** A customer can publish a read key to their own policy: to a customer asking how they govern their agents, to an auditor, to an underwriter. **That is shareable proof that does not require handing over control, an account, or a copy that immediately goes stale.**

**And it is what makes the document an underwriting input rather than an attachment.** The third brief of 11 September established that the only insurer underwriting agents by name requires a scoping statement of capabilities, autonomy, data access and callable tools. **A read key to a live, versioned, recomputing vault is a better answer to that request than a document, and nobody else can offer it.**

**The public and private versions the memo mentions are the library and the instance again.** The five example policies are public with published read keys, like the twenty five demonstrations already on the platform site. A customer's own policy is private, and they choose.

## The Rule That Decides Whether This Is A Business

**The first policy will be made by hand. If the second one costs the same, there is no business.**

**So the thing being built is not a document and not even a vault. It is the template plus the shape library.**

| Asset | What it is | Why it is the product |
|---|---|---|
| **The template vault** | The structure, the computation, the renderings | Cloned per customer. Written once |
| **The shape library** | The published grants per deployment shape, with provenance | **The marginal cost of a policy is the cost of the shape, and shapes are reused** |
| **The mandate question set** | The structured elicitation | The only per customer work that cannot be removed |

**Instrument the first five.** Time each one, count how many rows were derived rather than measured, count how many questions had to go to a human, and note which stage was slowest. **Publish it as a table.** It is the estate's honesty discipline, and it is the only pricing input anybody will have.

**And the target is explicit: the second policy of a shape already in the library should be minutes rather than days.** If it is not, the library is not doing its job and the flow needs changing before anything is priced.

## What This Does Not Try To Be

- **A vault schema.** The contents are listed. No file layout, no page structure and no identifier scheme is specified.
- **A price.** The ABP sits on the tiers set on 10 September and nothing here changes a number.
- **A test of any vendor's product.** Every scope and every capability claim here comes from published documentation read on 12 September. **Nothing was probed and nothing may be.**
- **A resolution of the four contradictions.** They are stated as unresolved with both sources, which is the only honest option available.
- **A design for the risk product's site.** Where the buy button goes is argued. Nothing is laid out.

## Honest Tensions

| Tension | Note |
|---|---|
| Starting with the connectors | It is the strongest argument available, and it means the first product names four large vendors on its first page |
| The contradictions | They are the demonstration, and publishing them invites a vendor to reply |
| Derived rather than measured | It is honest and it is nearly all of the first five, because the alternative is forbidden |
| The buy button on the risk product's site | It keeps the library free, and it puts a click between the argument and the purchase |
| The read key as proof | It is a real differentiator, and it asks a customer to publish something about their own weaknesses |
| The template as the product | It is what makes the second cheap, and it is invisible to the buyer, so nothing on the site sells it |
| Five policies this week | Stages one to four are genuinely shippable, and stage four is a conversation nobody has rehearsed |

## Open Questions

1. **What does the mandate question set look like for a connector shape?** For a coding agent the mandate is a job. For a mailbox it is closer to a relationship, and nobody has drafted the questions.
2. **Does the `material` property belong in the shared data or in the ABP?** It is a property of a capability in a context, which argues for the ABP, and it is reusable, which argues for the data.
3. **Who replies if a vendor disputes a contradiction?** The sourcing is theirs and the publication is ours.
4. **What is in the template vault on day one?** The minimum that makes stage ten possible is smaller than the full list above.
5. **Can a read key be revoked?** The proof story depends on it and the platform's answer was not checked.
6. **Which of the five gets built as the worked example on the front page?** Two and four are what somebody buys; one and three are what a stranger understands.
7. **How does a policy for a connector shape handle the enabled and disabled state?** A connector that exists and is switched off is not in the grant today and is one click from being in it, and neither the barrier model nor the label has a place for that yet.

## Relationship To Previous Briefs

**From the foundation document and the three briefs of 11 September**, it takes the four objects, the four barriers, the label and leaflet, and the rule that the ABP describes and does not judge, and it specifies how one gets made and delivered.

**From the correction of 11 September**, it takes the derived and never authored rule, and applies it to the vault's contents: everything in the delivered vault is derived except the mandate.

**From the teaching brief of 10 September**, it takes the sub delegation argument, and finds that the connector examples are that argument in the form a stranger already recognises.

**From the standards and licence briefs of 10 September**, it takes the licence matrix, and reorders the mapping so that the data protection regulation comes before the artificial intelligence regulation for these shapes.

**From the vault architecture brief of 10 September**, it takes the clone boundary and the pinning rule, and names the template vault as the thing on the paid side.

**From the marketing brief of 10 September**, it takes the prohibition on sending an unrequested packet, which is why four contradictions stay unresolved.

**From the site pack of 11 September**, it takes the rule that every claim about a named third party carries a source, a timestamp and no adjective, and this brief names four vendors under it.

## Key Claims

| # | Claim |
|---|-------|
| 1 | The grant a connector creates is user shaped and not data shaped, so the unit of restriction is the application and the tool, never the data |
| 2 | The narrowest mail scope that reads a message reads every message, and the only body excluding scope is used by none of these integrations |
| 3 | The default file search corpus is defined by its own publisher as files owned by or shared to the user |
| 4 | One vendor states that site specific narrowing is unsupported because the underlying search is tenant wide |
| 5 | Three shared access permissions in the corporate suite individually require no administrator consent, and the default domain posture permits the connection |
| 6 | So a connector grant is by construction a grant over material that was entrusted rather than owned, which is the sub delegation provision in a form a stranger recognises |
| 7 | The first standards mapping is the data protection regulation, because every organisation already has somebody accountable for it |
| 8 | In at least four places the advertised capability and the granted scope contradict each other, and that table is the demonstration no template can carry |
| 9 | Those contradictions may not be resolved by testing, so they are published as unresolved with both sources and a date |
| 10 | The capability grammar carries reach and not whose, and the minimum fix is a material property whose common value is mixed |
| 11 | Stages one to four of the flow ship this week, need five documents and a page, and require no access to anybody's environment |
| 12 | The template vault and the shape library are the product, because the business exists only if the second policy of a known shape costs minutes rather than days |

---

## Sources

All read 12 September 2026.

**Inside the estate.** The capability map at https://what-can-it-do.games.sgit.ai/map/index.html. The licence to operate demonstration at https://sgit.ai/demos/vaults/licence-to-operate/index.html. The platform site and its demonstrations at https://sgit.ai/llms.txt. The foundation document and the four briefs of 11 September.

**What a mail connector grants.** Scope definitions at https://developers.google.com/workspace/gmail/api/auth/scopes. The official server's scope list at https://developers.google.com/workspace/guides/configure-mcp-servers and its tool reference at https://developers.google.com/workspace/gmail/api/reference/mcp. The connector description at https://claude.com/connectors/gmail.

**What a file connector grants.** Scope definitions and classifications at https://developers.google.com/workspace/drive/api/guides/api-specific-auth. The default corpus definition at https://developers.google.com/workspace/drive/api/reference/rest/v3/files/list. The connector description at https://claude.com/connectors/google-drive. The shared drive parameters at https://developers.google.com/workspace/drive/api/guides/enable-shareddrives.

**The corporate suite.** The connector security guide, including the statement that site specific permissioning is unsupported because the underlying search is tenant wide, at https://support.claude.com/en/articles/12684923-microsoft-365-connector-security-guide. Consent defaults at https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent. Permission descriptions read from a mirror of the vendor reference rather than the canonical page, which truncates.

**The storage service.** The official server and its eight scopes at https://help.dropbox.com/integrations/connect-dropbox-mcp-server. Access types at https://developers.dropbox.com/oauth-guide.

**Administrative controls and defaults.** Application access control at https://knowledge.workspace.google.com/admin/apps/control-which-apps-access-google-workspace-data, including that the unconfigured default permits third party access.

**The protocol.** The specification at version 2026-07-28, its authorization section requiring least privilege scope selection, and its statement that tool annotations must be considered untrusted, at https://modelcontextprotocol.io/specification/.

**Incidents, for context and not for the policies.** A zero click injection against a corporate assistant described at https://arxiv.org/html/2509.10540v1. A zero click exfiltration through a mail connector reported at https://thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.html. A browser extension issue patched in May 2026 reported at https://hackread.com/claudebleed-vulnerability-hackers-claude-chrome-extension/. A chained issue patched on 18 August 2026 at https://www.varonis.com/blog/cosnitch. The framing of the three conditions at https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/.

**The regulatory hook, and the gap.** The national regulator's assessment of 8 January 2026 at https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/. No regulator publication was found addressing third party material in a mailbox disclosed by the account holder's own consent.

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
